Sentrix

ISO 27001 guide · Clause 9

9.2 — Internal audit

Clause 9.2 requires a periodic, independent internal audit checking that the ISMS conforms to your rules and to the standard, run through a defined programme.

By Sentrix · Published 2026-07-16

The requirement that gives your ISMS an independent check-up before an external auditor gets the chance to find something you missed.

Mandatory requirement

In plain language

Sub-clause 9.2 requires you to periodically check, through an audit independent of the people who run the ISMS day to day, whether the system actually conforms to your own rules and to the standard—and to run that checking through a defined, repeatable programme rather than an ad hoc exercise.

How these requirements fit together

9.2.1 sets the destination: your ISMS needs planned, periodic internal audits confirming it conforms to your own requirements and to the standard, and that it is effectively implemented and maintained. 9.2.2 is the vehicle that gets you there—the actual programme defining how often audits happen, what criteria and scope apply each time, who is qualified to conduct them objectively, and how results get reported and retained. An organization that skips 9.2.2 and just does an audit "when there is time" technically has no internal audit programme at all, regardless of how thorough any individual audit was.

Going further

Need hands-on support running your internal audit programme? See our ISO 27001 certification support service. Parent clause: Clause 9 Performance evaluation.

Sources

Frequently asked questions

Who can perform the internal audit?
Anyone independent of the area being audited: an internal employee from a different team, or an external contractor for smaller organizations without enough internal separation. The requirement is objectivity and impartiality, not a specific credential. An auditor who reviews their own area of responsibility is the single most common finding against this sub-clause.
What is the difference between 9.2.1 and 9.2.2?
9.2.1 sets the goal: planned internal audits confirming the ISMS conforms to your requirements and to the standard, and that it is genuinely implemented and maintained. 9.2.2 is the programme that gets you there—frequency, criteria and scope, selection of independent auditors, reporting and retention. Without a programme, an audit done "when there is time" does not count.
Why does internal audit weigh so heavily at certification?
Because its findings are the single best predictor of how the certification audit will go. If your own internal audit consistently finds nothing, either the ISMS is unusually mature or the audit is not looking hard enough, and the external auditor will probe to find out which. An audit that also tests effective implementation, not just documentation, is more credible.

Let's talk about your compliance program.

Last updated: 2026-09-17